Skip to main content

maskflow-evidence

A metadata-only, verifiable record of what MaskFlow masked — never the values themselves. Publishing the schema and shipping the emitters in the open lets any user confirm, by reading the code, exactly what leaves their environment.

Part of MaskFlow. MIT, free forever, no telemetry.

What an event looks like

{"event_id":"…","ts":"2026-09-07T12:00:00Z","session_id":"…","service":"support-bot",
 "environment":"prod","entity_type":"AADHAAR","count":1,"score":0.98,
 "recognizer":"pattern:AADHAAR","action":"masked","provider":"openai","model":"gpt-4o",
 "pack_version":"0.5.0","engine_version":"0.6.0"}

There is no field that can carry free text. Every string is a bounded slug; there is no place for a detected value, a placeholder, or the mapping between them. This is enforced structurally in schema.py and in CI by tests/test_schema_metadata_only.py.

Off by default

Nothing is emitted unless you turn it on. In .maskflowrc:

[evidence]
enabled     = true
sink        = "file"          # stdout | file | syslog | webhook | otlp
path        = "evidence.log"
service     = "support-bot"
environment = "prod"

The gateway reads MASKFLOW_GATEWAY_EVIDENCE_* environment variables with the same names.

Sinks

sink transport extra
stdout one JSON line per event —
file size-rotated JSON lines —
syslog SysLogHandler —
webhook POST JSON per event maskflow-evidence[webhook]
otlp OpenTelemetry log records maskflow-evidence[otlp]

What is deliberately not collected

Raw values, masked values, the mapping, request/response bodies, prompt text, and any user identifier beyond a caller-supplied opaque session_id. See docs/evidence.md for the full statement.

Metadata

Release files for maskflow-evidence 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maskflow-evidence 0.1.1
File Size Uploaded
maskflow_evidence-0.1.1.tar.gz 18.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maskflow-evidence 0.1.1
File Interpreter ABI Platform
maskflow_evidence-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 37.0 kB

Release files / maskflow_evidence-0.1.1.tar.gz

Download URL maskflow_evidence-0.1.1.tar.gz
Size 18.7 kB
Tags Source
SHA-256 checksum
How to use checksums
685b2155cd74f98d0c92eb0e9aade7b0ad4b8a33d62401d9445b7a52a9d85769
BLAKE2b-256 checksum
How to use checksums
440419c01cc3962ae6187b1b0c31eada17629e1d6981d719106fb626360e8554
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / maskflow_evidence-0.1.1-py3-none-any.whl

Download URL maskflow_evidence-0.1.1-py3-none-any.whl
Size 18.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
78beab3bf03de36ee630c1f78742fa3aecb05016a1f7112e74d10d6e77e76790
BLAKE2b-256 checksum
How to use checksums
4c5aa1cc6fb87abdcd2dff73a2ef33a6ff500d78f38a8f563229c0007879b99f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page